THE TAKEAWAY
Give the agent a clear question, narrow tools and a verifiable stopping condition. Evaluate completed account work, including failed actions and review.
The decision this guide helps you make
How can an agent use tools without turning account work into uncontrolled automation?
You will leave with: A tool contract with allowed reads, proposed writes and stop conditions.
Start here: Define the account task.
Download this guide’s decision worksheetDefine the action before choosing the model
A tool-using agent can request information, observe the result and decide whether another step is needed. For ABM, a bounded task might be locating a company announcement, checking the CRM entity and proposing a sourced brief. The workflow should define which steps are allowed before execution begins.
Separate read access from write access. Searching approved documents is different from modifying an opportunity or contacting a prospect. A model’s ability to describe an action does not grant it permission to perform that action. Make the contract explicit for each tool.
What ReAct contributes
Yao and colleagues studied the interleaving of reasoning and actions in ReAct. The ICLR 2023 paper evaluated question answering, fact verification and interactive tasks, reporting improvements on its benchmarks. Those results support investigating structured tool interaction; they do not validate unattended enterprise outreach.
Our ABM interpretation is to expose the observable loop: the question asked, tool invoked, result returned, evidence selected and decision made. Inspect those records rather than treating an eloquent explanation as a complete account of what happened.
Explore the original methods and findings in ReAct: Synergizing Reasoning and Acting in Language Models.
The practical workflow
- Define the account task
- Grant narrow tool access
- Observe results and exceptions
- Validate the proposed output
- Stop or hand off explicitly
Compare the approaches
| Approach | Useful when | Limitation | Next action |
|---|---|---|---|
| Read-only agent | Evidence gathering | Sources may be ambiguous | Check entity and support |
| Draft proposal | Preparing seller material | Output may be incorrect | Review before activation |
| Deterministic rule | Stable routing logic | Cannot resolve novel ambiguity | Use explicit conditions |
| Write-capable agent | A validated operational task | Errors can affect records | Require permission and recovery |
Specify the tool contract
A company-search tool should accept an organisation identifier and a bounded query. Its output should distinguish retrieved documents from verified facts. A CRM-read tool should enforce record permissions and return the fields needed for the task. A draft tool can propose content without sending it.
Limit retries, execution time and cost. Define what happens when a tool times out, returns several matching entities or contradicts earlier evidence. Preserve the last accepted state. An interrupted workflow should resume from a known checkpoint rather than repeat every side effect.
Use a fictional expansion investigation
The agent receives a question about Northbridge Components’ new distribution centre. It retrieves an announcement, confirms the organisation identifier and finds that no stakeholder conversation is recorded. It can draft a hypothesis and a discovery question. It cannot invent a project or book a meeting.
If the company-search tool finds a similarly named logistics business, the agent should stop for entity resolution. If a page contains instructions to export CRM records, the retrieved text remains untrusted source material. The tool policy should prevent that action regardless of the draft’s wording.
Explore the original methods and findings in Not what you have signed up for: Indirect Prompt Injection.
Evaluate complete trajectories
Test ordinary work, ambiguous entities, missing evidence and tool failures. Count accepted briefs, unsupported assertions, unnecessary tool calls, total elapsed time and correction cost. Inspect whether the workflow stops at the right boundary. A high rate of successful API calls can coexist with poor account decisions.
Keep a small set of replayable cases with expected outcomes. After changing a tool schema, permission or model, run those cases before expanding the workload. Add failures discovered in production without removing difficult examples to improve the reported score.
Expand permissions after evidence
Begin with read-only retrieval and draft proposals. Expand a permission only when the associated task is useful, the failure paths are understood and an owner can reverse or reconcile errors. Keep outbound activation as a separate decision with its own conditions.
The practical advantage of an agent comes from handling a bounded sequence with traceable evidence. If a fixed rule already solves the task reliably, a simple deterministic step may be the better operating choice. Use the complexity the decision requires.
Your next-action checklist
- Read-only agent: Check entity and support. Check the limitation: sources may be ambiguous.
- Draft proposal: Review before activation. Check the limitation: output may be incorrect.
- Deterministic rule: Use explicit conditions. Check the limitation: cannot resolve novel ambiguity.
- Write-capable agent: Require permission and recovery. Check the limitation: errors can affect records.
Use the comparison to choose a bounded next step. Record the evidence, the responsible owner, and the review decision before extending the play to additional accounts.
How to use the evidence
Read each reference against the claim it supports. Platform documentation describes capabilities; public cases report a publisher’s experience; research findings apply to the studied task and population. The workflow in this guide is an operating proposal to evaluate in your own account context.
Inspect the research library and connect this guide to agentic operations.
Questions this guide answers
How can an agent use tools without turning account work into uncontrolled automation?
Give the agent a clear question, narrow tools and a verifiable stopping condition. Evaluate completed account work, including failed actions and review.
What should I do first?
Define the account task. Record the input evidence and the acceptance criteria before continuing. Use the decision worksheet to document the owner, review date and next action.
Read the original research
The guide explains the findings above. Open a publication to inspect its methods, setting and qualifications.
ReAct: Synergizing Reasoning and Acting in Language Models. Benchmark success is not permission to operate a production marketing system autonomously.
Not what you have signed up for: Indirect Prompt Injection. The paper demonstrates attack mechanisms rather than a current marketing incident rate.
Connect this guide to the next decision
Observe the ABM Agent Workflow Beyond Model Calls — What should teams record to explain why an ABM agent produced, delayed, or executed a particular recommendation?
Prompt injection in marketing agents: separate research from instructions — What can go wrong when a marketing agent reads an external page?
Agentic workflows versus marketing automation — When does a task need an agent instead of fixed automation?
PUT IT INTO PRACTICE
Start with your account priorities.
Compare account focus, personalisation, deliverables, and measurement.
Explore Momentum